Description
The package total.js before 3.4.8 are vulnerable to Remote Code Execution (RCE) via set.
Remediation
References
https://github.com/totaljs/framework/commit/c812bbcab8981797d3a1b9993fc42dad3d246f04
https://snyk.io/vuln/SNYK-JS-TOTALJS-1077069
Related Vulnerabilities
CVE-2017-16008 Vulnerability in npm package i18next
CVE-2023-0842 Vulnerability in maven package org.webjars.npm:xml2js
CVE-2022-41931 Vulnerability in maven package org.xwiki.platform:xwiki-platform-icon-ui
CVE-2023-35145 Vulnerability in maven package org.jenkins-ci.plugins:sonargraph-integration
CVE-2021-21344 Vulnerability in maven package com.thoughtworks.xstream:xstream